HTTP Servers
HTTP Servers group inbound HTTP APIs. Each server has a slug used in the public base URL. Each API has its own slug and a free-form handler workflow — there is no linear resource mapping.
They are not event handlers you create from the Event handlers menu (tables, mail, WhatsApp). They are not APIs under Configuration (those call out to other systems).
Open HTTP Servers
Open Build → HTTP Servers.
Create a server
Click Create HTTP server. Set:
| Field | Purpose |
|---|---|
| Name | Label in the list |
| Slug | Base path in the public URL (letters, numbers, underscores, hyphens) |
| Description | Optional |
The base URL is on the company subdomain:
https://<company>.vettero.com/events/http/{workspace id}/{server slug}
Workspace id is the workspace Id (slug), not a database id. The server slug cannot be changed after you create it.
Open the server and use Settings. Edit changes the name or description. Turn Availability off to reject inbound requests until you enable it again. Delete moves the server and its APIs to trash.
OpenAPI schema URL
On the server Settings tab, turn on OpenAPI schema URL. You must set authentication (basic, API key, or bearer) — the spec is not public.
The URL looks like:
https://<company>.vettero.com/events/http/{workspace id}/{server slug}/openapi.json
GET returns an OpenAPI JSON document for every active API on that server (paths, methods, query/body/response schemas, and each API’s auth type). Fetching this URL does not run any API workflow.
Turn the option off to stop serving the spec. openapi.json is reserved and cannot be used as an API path.
Add an API
Open a server. Click Create API. Set a name and the HTTP settings:
| Setting | Purpose |
|---|---|
| Path | API slug — appended to the server URL. Cannot be changed after you create the API |
| Methods | Allowed methods. Empty: all |
| Auth | None, basic, API key, or bearer |
| CORS | Allowed browser origins. Empty: all |
| Wait for the flow | Wait for the workflow (sync response) or reply immediately with accepted |
| Query / body / response schemas | Always available. Turn on validate request / validate response to enforce them |
Vettero creates a handler workflow. Open it in the workflow builder to add blocks. You cannot switch this API to linear resource mapping.
The full URL is:
https://<company>.vettero.com/events/http/{workspace id}/{server slug}/{api slug}
When to use
- Partner or SaaS systems that POST or GET into Vettero
- A small set of related endpoints that share a base path
- Sync responses when the caller needs a result; async when a quick accepted is enough
Limits
- Inactive servers and inactive APIs reject inbound requests.
- The OpenAPI schema URL (when enabled) requires its own auth and does not run API workflows.
- Callers get a rejected JSON body with a
reasoncode:- Unknown path or a method that is not enabled on that path — HTTP 404 (
HTTP_NOT_FOUND). Auth is not checked. - Failed auth — HTTP 401 (
HTTP_AUTH_FAILEDorHTTP_AUTH_MISCONFIGURED) - Inactive server or API — HTTP 503 (
HTTP_SERVER_INACTIVE/HTTP_HANDLER_INACTIVE) - Run condition did not match — HTTP 422 (
HTTP_CONDITION_NOT_MET)
- Unknown path or a method that is not enabled on that path — HTTP 404 (
- Unknown paths are recorded on the server Logs tab as HTTP 404.
- API slugs must be unique on that server.
- Deleted servers and APIs go to Trash. Deleting a server also deletes its APIs.
- Public URLs that used a handler id in the path are no longer used.
Related
- Event handlers — tables, mail, WhatsApp
- Schedule — one-time jobs and repeating cron
- Workflows — extend the API handler flow
- Trash